Impact
A command injection flaw exists in the /cgi-bin/wireless.cgi script of the Wavlink WL-NU516U1-A router. The subroutine sub_401D68 processes POST parameters SSID2G2, SSID5G2, AuthMethod2, and WPAPSK12, and an attacker can embed arbitrary shell commands into these parameters. The flaw allows the execution of those commands on the router’s firmware and therefore remote code execution. The vulnerability is described by CWE‑74 (Command Injection) and CWE‑77 (Improper Restriction of Operations within the Command Shell).
Affected Systems
The affected product is the Wavlink WL‑NU516U1‑A router running firmware version M16U1_V240425. The issue resides in the HTTP interface that processes POST requests to /cgi-bin/wireless.cgi. Only this model and firmware version are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate baseline risk. The EPSS score of 1% indicates a low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The official alert notes that the flaw has been publicly disclosed and that a fixed firmware revision has been released. The likely attack vector is remote HTTP POST traffic directed at the device’s web management interface, which is reachable from network or management plane connections.
OpenCVE Enrichment